# Local agent

> Reading estates that cannot be reached from the internet, without credentials leaving your network.

The local agent runs inside your network and reports out, for estates that
cannot be reached from outside: an air-gapped environment, or a private cloud
with no inbound path.

## How it works

You run the agent on a host that can reach the estate. It polls locally and
sends results outbound to Blueprintr. There is no inbound connection, so no
firewall rule permitting traffic into your network is required.

## Credentials stay put

> [!IMPORTANT]
> Credentials for a locally-polled estate are held on-premises by the agent and
> are never sent to Blueprintr. Setting up the agent never asks you to paste
> them into a hosted form.

## What it sends

The polled resource inventory, the same data a hosted poll produces. The same
[scope](/foliums/blueprintr-user-guide/continuum/scopes-and-polling) decisions
apply.

## Operating it

The agent is versioned and updated separately from the platform, and is
distributed for you to run on infrastructure you control. Your account contact
provides it along with the enrolment credentials.
